vendor:
HIOX Random Ad
by:
Stack
7.5
CVSS
HIGH
Arbitrary Add Admin User Vulnerability
264
CWE
Product Name: HIOX Random Ad
Affected Version From: 1.3
Affected Version To: 1.3
Patch Exists: NO
Related CWE: N/A
CPE: a:hscripts:hiox_random_ad:1.3
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
HIOX Random Ad 1.3 Arbitrary Add Admin User Vulnerability
HIOX Random Ad 1.3 is vulnerable to an arbitrary add admin user vulnerability. An attacker can exploit this vulnerability to add an admin user to the application. This vulnerability is due to the application not properly validating user-supplied input. An attacker can exploit this vulnerability by sending a crafted HTTP request to the application.
Mitigation:
Ensure that user-supplied input is properly validated before being used by the application.